注册表里删除
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<w><%SystemRoot%\WinRaR.exe> [N/A]
<mm><%SystemRoot%\sourro.exe> [N/A]
<zx><%SystemRoot%\winadr.exe> [N/A]
找出文件:
C:\Program Files\Common Files\SyInfo.bps
C:\WINDOWS\system32\rsjzapm.dll
C:\WINDOWS\system32\avzxamn.dll
C:\WINDOWS\system32\avwlamn.dll
依次改名为1.DLL 2.DLL 3.DLL 4.DLL
重起进入安全模式(开机按F8选择安全模式)
删除1.DLL 2.DLL 3.DLL 4.DLL
清除注册表项
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{72204F90-5CD6-41B1-BD69-62CD84C9FB24}><C:\Program Files\Common Files\SyInfo.bps> []
<{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}><C:\WINDOWS\system32\rsjzapm.dll> [N/A]
<{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINDOWS\system32\avzxamn.dll> [N/A]
<{1960356A-458E-DE24-BD50-268F589A56A1}><C:\WINDOWS\system32\avwlamn.dll> [N/A]
把注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><avzxamn.dll> [N/A]
设置为空~~
重起,全盘杀毒